CVE-2024-43027: DrayTek VIGOR2960 Firmware

High severity, CVSS 8.0. EPSS: 1.3% chance of exploitation in the next 30 days.

DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action parameter at cgi-bin/mainfunction.cgi.

Affected products

  • DrayTek VIGOR2960 Firmware: before 1.5.1.5 (fixed in 1.5.1.5)
  • DrayTek VIGOR300B Firmware: before 1.5.1.5 (fixed in 1.5.1.5)
  • DrayTek VIGOR3900 Firmware: before 1.5.1.5 (fixed in 1.5.1.5)

Published 2024-08-21. Last modified 2026-06-17.